CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3282

As cited

Copy frozen at (site build).

threat intel

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Dysphoria, an IoT botnet, has evolved its command and control infrastructure to use blockchain-based naming services and victim-device relays following a March law-enforcement takedown of JackSkid infrastructure. The architectural changes are intended to increase the botnet's resilience against disruption efforts. Researchers from CNCERT and XLab documented these technical adaptations.

Why it matters: Organizations operating IoT devices face increased risk from botnets employing decentralized command infrastructure that traditional takedowns and domain-blocking may not fully disrupt; defenders should monitor for IoT devices exhibiting unusual outbound blockchain-related traffic and relay behavior.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary